WKPdwatkins/PTK Project
Original author(s)Dario Forte
Developer(s)DFLabs Inc
Stable release
version 2.0
PlatformLAMP
Available inJavaScript, PHP, Perl
TypeDigital Forensics
Websitehttp://ptk.dflabs.com/

PTK Forensics (PTK) is a downloadable software tool utilized by digital forensics investigators for capturing and examining disk and memory images from computers suspected to contain evidentiary material in criminal and civil legal matters. The tool works in conjunction with The SleuthKit (TSK), an open-source forensics software apparatus widely used by investigators in that pursuit.

Functions

edit

TSK scans the hard drives and extracts file images from Windows, Unix and Linux systems. PTK runs as a GUI interface for TSK, acting to compile and index the disk image outputs. These outputs are then stored in a SQL database and can be searched extensively for evidence and trending pertinent to the case.

Amongst other operations, PTK handles the complex process of management and comparison of hash sets tied to the images being examined.[1] The hash algorithms employed are SHA-1 and MD5, considered to be the most widely accepted hash values for use in digital forensics[2]. This process ensures or, in some instances, disproves the consistency of the image when compared to the original.

References

edit
  1. ^ hash set mgmt Cite error: The named reference "SansArticle1" was defined multiple times with different content (see the help page).
  2. ^ Hash set mgmt Cite error: The named reference "CommonHash" was defined multiple times with different content (see the help page).

Other Products

edit

IncMan (Incident Manager) - http://incman.dflabs.com

DIM (Digital Investigation Management) - http://dim.dflabs.com

edit


Category:Computer forensics Category:Free security software

Category:Digital forensics software